Multiple vulnerabilities have been identified in IBM Domino Web Server:
- CVE-2015-2014: open redirect. A remote attacker can exploit it by enticing their victim into following a specially crafted URL in order to redirect to an arbitrary website
- CVE-2015-2015: cross-site scripting. An authenticated remote attacker could exploit it by enticing their victim into following a specially crafted URL in order to execute arbitrary JavaScript or HTML code. This vulnerability is located in Domino Directory template (pubnames.ntf).
IBM has released versions 8.5.3 Fix Pack 6 Interim Fix 9 and 9.0.1 Fix Pack 4 versions of Domino which fix these vulnerabilities. To enable the fix for CVE-2015-2014 vulnerability, you must add the following setting to the Domino Server's "notes.ini" file: "DominoValidateRedirectTo=1".